Description
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.
Published: 2026-07-24
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authentication in the PAM configuration allows a local attacker to log in as a uid=0 account without a password by creating an entry in /etc/passwd with an empty password field. The result is a root shell, giving the attacker full control of the affected device. This flaw falls under CWE-287 (Improper Authentication) and CWE-521 (Plaintext Storage of Password).

Affected Systems

All Loytec LINX firmware products including LIP‑ME201C, L‑INX, L‑GATE, L‑ROC, L‑IOB, L‑DALI, L‑VIS, and L‑PAD are affected through firmware versions up through 8.4.16.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, and the EPSS score of less than 1% signals a low yet non-zero likelihood that the vulnerability will be actively exploited. Because the attack requires local access to the device, the flaw is not remotely exploitable, but it remains a significant concern in environments where physical or local console access is possible. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 3, 2026 at 20:16 UTC.

Remediation

Vendor Solution

Upgrade to firmware version 8.4.18.


OpenCVE Recommended Actions

  • Upgrade the device firmware to version 8.4.18 as recommended by Loytec
  • Remove any /etc/passwd entries that contain an empty password field or ensure that all passwords are properly set
  • Enforce physical security controls to limit local console access to authorized personnel

Generated by OpenCVE AI on August 3, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc
Vendors & Products Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.
Title Loytec LINX firmware: Improper Authentication in PAM configuration
Weaknesses CWE-287
CWE-521
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-07-24T14:57:20.563Z

Reserved: 2026-06-17T09:48:17.638Z

Link: CVE-2026-12504

cve-icon Vulnrichment

Updated: 2026-07-24T14:57:15.943Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T15:17:11.157

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-12504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses